Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-84379

Опубликовано: 02 сент. 2026
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

HTTPX2 is a next generation HTTP client for Python. Prior to 2.11.0, FileField.render_headers() in src/httpx2/httpx2/_multipart.py directly interpolates attacker-controlled content_type values and custom headers from the files= three-element (filename, content, content_type) tuple and the files= four-element (filename, content, content_type, headers) tuple into multipart/form-data part headers without validating header names or values. CR or LF characters can terminate a part header, inject additional part headers, or end the part header block early, allowing a downstream multipart parser to treat attacker-supplied lines as genuine headers and potentially alter part semantics or bypass header-based checks. This issue is fixed in version 2.11.0.

A flaw was found in HTTPX2, a Python HTTP client. A remote attacker could exploit this vulnerability by sending specially crafted multipart/form-data requests. The FileField.render_headers() function fails to validate Content-Type values and custom headers, allowing the injection of Carriage Return (CR) or Line Feed (LF) characters. This could lead to the injection of arbitrary part headers, potentially altering the interpretation of multipart data or bypassing security checks by a downstream parser.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Lightspeed Corelightspeed-core/lightspeed-stack-rhel9Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-automl-rhel9Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-kserve-autogluon-server-rhel9Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-kserve-storage-initializer-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-93
https://bugzilla.redhat.com/show_bug.cgi?id=2527696httpx2: HTTPX2: Multipart header injection via unvalidated input

EPSS

Процентиль: 18%
0.00261
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
13 дней назад

HTTPX2 is a next generation HTTP client for Python. Prior to 2.11.0, FileField.render_headers() in src/httpx2/httpx2/_multipart.py directly interpolates attacker-controlled content_type values and custom headers from the files= three-element (filename, content, content_type) tuple and the files= four-element (filename, content, content_type, headers) tuple into multipart/form-data part headers without validating header names or values. CR or LF characters can terminate a part header, inject additional part headers, or end the part header block early, allowing a downstream multipart parser to treat attacker-supplied lines as genuine headers and potentially alter part semantics or bypass header-based checks. This issue is fixed in version 2.11.0.

CVSS3: 5.3
nvd
14 дней назад

HTTPX2 is a next generation HTTP client for Python. Prior to 2.11.0, FileField.render_headers() in src/httpx2/httpx2/_multipart.py directly interpolates attacker-controlled content_type values and custom headers from the files= three-element (filename, content, content_type) tuple and the files= four-element (filename, content, content_type, headers) tuple into multipart/form-data part headers without validating header names or values. CR or LF characters can terminate a part header, inject additional part headers, or end the part header block early, allowing a downstream multipart parser to treat attacker-supplied lines as genuine headers and potentially alter part semantics or bypass header-based checks. This issue is fixed in version 2.11.0.

CVSS3: 5.3
debian
14 дней назад

HTTPX2 is a next generation HTTP client for Python. Prior to 2.11.0, F ...

CVSS3: 5.3
github
8 дней назад

HTTPX2: Multipart part header injection via unvalidated file Content-Type and custom headers

EPSS

Процентиль: 18%
0.00261
Низкий

5.3 Medium

CVSS3